Missing Authentication Vulnerability in HYPR Passwordless for Windows
CVE-2026-4522

6.7MEDIUM

Key Information:

Vendor

Hypr

Vendor
CVE Published:
25 June 2026

What is CVE-2026-4522?

A critical vulnerability exists in the HYPR Passwordless solution that allows an attacker to intercept credentials due to missing authentication measures for vital functions. This flaw primarily affects Windows systems with versions prior to 11.1.1, leaving users susceptible to unauthorized access and potential data breaches. It is essential for users of the affected product to mitigate this risk by upgrading to the patched version.

Affected Version(s)

Passwordless Windows 0 < 11.1.1

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.